Back to interests

Interests

Security & CTF

Following questions about Linux led me into security. I learn by reporting findings through HackerOne within each program's scope and by working through challenges on TryHackMe.

Security started for me with a simple question while using Linux: why does it behave this way? Looking for the answer pulled me in.

HackerOne is my main platform now. I read each program's policy and scope first, then report issues I find in real services. I break behavior down into small pieces and separate what I confirmed, what is needed to reproduce it, and what I still do not know. To keep research safe, I also build internal tooling that evaluates scope before execution and keeps decisions and evidence in an audit log.

I play TryHackMe and CTFs solo. Web, pwn, reverse engineering, crypto: I try to build broad fundamentals rather than lean on one category. I still get stuck often, but nothing quite matches the feeling of a solve, and it is the training ground for working in real environments.

Building software gives me related questions about permissions and state. My personal AI tools taught me that being signed in does not mean an operation is authorized. In an operational tool, I made changes to an email's recipients or content invalidate its previous approval. Tracking who authorized which action against which version connects development with research for me.

When writing, I try to keep observed behavior separate from possible impact. Passing tests, checking a real environment, and leaving something untested are different states. I want readers to be able to follow the evidence, rather than just read an impressive claim. This site focuses on research and development lessons without publishing undisclosed report details.